|
|||||||||||||||||||||||||||||||||||
|
13 Reviews
|
Average Customer Review
Share your thoughts with other customers
Create your own review
|
|
Most Helpful First | Newest First
|
|
15 of 16 people found the following review helpful:
4.0 out of 5 stars
Best security infrastructure book I've read,
By Southern California .NET User Group (SoCalNETug.org) - See all my reviews
This review is from: .NET Framework Security (Paperback)
This is the best book about the security infrastructure of Microsoft .NET Framework that I have ever read. This book has brought me the overall picture of the .NET security system: How does the system work and interact with the existing security system on Win NT platform? In addition, the book is clearly written, well- organized, and full of in-depth information. Overall, I consider this is an excellent book which could satisfy the security needs for all .NET developers and administrators. This book is divided into five sections: 1. Introduction to the .NET Developer Platform Security: This section provides an introduction to the .NET Framework platform and all of the new security features available. Although this section describes only brief information, I still recommend that every one should read it first before jumping to the others. The first section "provides common background material for the topic-specific discussions in the remainder of the book." 2. Code Access Security Fundamentals: This section is really difficult. I felt overwhelmed with too many new concepts and skipped it. However, after reading some chapters of the next section, I realized that the code-based security concept is the keystone for the entire security system. I had to come back to section two and read it carefully. Learn from my lesson, you should try to understand it at the first time you read it. 3. ASP.NET and Web Services Security Fundamentals: This section provides brief information about server-side security features of ASP.NET and Web Services. 4. .NET Framework Security Administration: This section provides a comprehensive guide to administer .NET Framework security. It shows you when and how to make modifications. Some topics are presented as tutorials. It is very to easy to capture and follow the steps. 5. .NET Framework Security for Developers The final section is devoted to developers. It provides all needed information to build secure assemblies, web sites, applications, and web services. It also provides an in-depth introduction to the cryptography library shipping in the .NET Framework and to XML digital signatures. For developers who don't have enough time to read the whole book, this is the section that you should spend your time on. -- Review by Trung N.
14 of 15 people found the following review helpful:
2.0 out of 5 stars
Good material on CAS, TERRIBLE material on ASP.NET Security,
By
Amazon Verified Purchase(What's this?)
This review is from: .NET Framework Security (Paperback)
Four of the authors do a reasonably good job explaining the whole concept of CAS. At times, they seem to be repeating themselves, but the result is that you cannot walk away without understanding what they wanted you to understand because of this repetition.The downside of this book is the material by Kevin T. Price. They delegated the ASP.NET/Web security to him. Much of his work is a cut and paste of the SDK docs. For his examples, he uses the grid layout of ASP.NET, which makes the declarative code completely unreadable. He leaves in all of the code generated by Visual Studio.NET, despite its irrelevance. He spends a great deal of time discussing IIS configuration, which you might argue is not relevant to the subject matter at hand (this should be a very specialized book, and it is everywhere else). He refers us to a code download on the Sam's website - unfortunately, Sam's is not the publisher of this book. He puts in some sample JSP code for no apparent reason, apparently to teach us about diversity in the web environment. When you buy a book on .NET Framework Security, it is probably because you are interested in .NET, and not because you are interested in the web development ecosystem. Finally, his grand finale chapter is on writing a secure web application. All he manages to achieve here is to create a forms auth login page. Even more troubling is the fact that this sample - in a book on *security* - has a glaring SQL Injection Vulnerability. The one thing he creates is completely and disturbingly wrong. Web developers who buy this book to write more secure applications are likely to end up writing even worse applications by implementing his ideas. Read this book if you want to learn about CAS. Do not stop at this book if you actually need to write secure web applications - in fact, don't even start here. You're better off sticking with the PAG materials.
9 of 9 people found the following review helpful:
5.0 out of 5 stars
The definite security reference for .NET applications,
By A Customer
This review is from: .NET Framework Security (Paperback)
Make no mistake,as you will get your hands wet programming Micrsosoft's "managed code" (C#, VB or ASP.NET apps), you will eventually encounter the all pervasive and extensive security system that is integrated in .Net.This book is the definite security reference and guide to the new programming platform that Micrsosoft has shipped - and the only book of its kind on the market as far as I can see. It has been written by the people who have designed and implemented the security features and infrastructure in the .NET Framework that ASP.NET, C#, VB or Managed C++ applications run on. Its stuffed with sample code and hands-on tips, and comes with extensive sections geared specifically towards developers and admins. Chapters are well contained and you get the kind of insider information only the people who have actually build and designed the system would be able to give you. 800 plus pages of security information for the Amazon price is quite a good bang for the buck,so I highly recommend this book as I think it will be a good learning aid in trying to understand .NEt security and remain valuable as a reference work afterwards.
7 of 7 people found the following review helpful:
4.0 out of 5 stars
A great starting point,
By
This review is from: .NET Framework Security (Paperback)
This book is an excellent starting point for understanding the .NET framework security mechanisms. Especially code access security. Its only real failings are the lack of depth in a few obscure areas (details around simulating permissions that might be granted to an app deployed via the Internet and hosted in IE). You could glean most of this information from the internet and spend a month doing it, like I did. Or spend $$$ and few hours reading this well written book.
3 of 3 people found the following review helpful:
5.0 out of 5 stars
Very in-depth, excellent,
By A Customer
This review is from: .NET Framework Security (Paperback)
This was awesome. The authors picked apart each new piece of the security model and explained it most clearly. What really helped me though were the code samples - one of those people who learns by doing more than just listening. Definately one to have not only as a reference, but to get a firm understanding of what the underlying structure of .NET Security is all about.
3 of 3 people found the following review helpful:
5.0 out of 5 stars
This is the book you're looking for.,
By Erik W. Davis "Erik" (St. Paul, MN) - See all my reviews
This review is from: .NET Framework Security (Paperback)
It's probably not going to make your in-laws love you, but it is the right book for .Net. Like all things digital, .Net programming has already resulted in a number of books, mostly of shoddy quality. This book, however, written by the folks who ought to know (Sebastian Lange and company), is the best place to start, and until they update it, the best place to stay.But it won't make your in-laws love you.
5 of 6 people found the following review helpful:
4.0 out of 5 stars
Good Information,
By Elijah D "dev1zero" (Bothell, WA United States) - See all my reviews
Amazon Verified Purchase(What's this?)
This review is from: .NET Framework Security (Paperback)
When I was assigned the task of finding out what .NET security was all about in the web environment, I didn't know what I was getting into. The whole .NET security infrastructure is really a handful. This book helps the reader understand what its all about.Another thing I like about the book is the fact that it has short chapters. This made it easier for me to read through it with above average speed.
10 of 15 people found the following review helpful:
1.0 out of 5 stars
A dictionary of .Net security terms,
By A Customer
Amazon Verified Purchase(What's this?)
This review is from: .NET Framework Security (Paperback)
The book is organized like a dictionary of .Net security terms. It failed to convey the cohesiveness of the security modules. The code fragments are littered like pieces of puzzle that the authors are expected to thread together, but did not. I didn't find the class API listing useful without implementation context to associate their usage to. Furthermore, the book lacked good editing. It's frustrating to read dangled sentence fragments interwined with code fragments. The book does not worth its weight. Waste your hard earned money on this book if you believe in you have a telepathy connection to the authors.
5.0 out of 5 stars
This is the book you're looking for.,
By Erik W. Davis "Erik" (St. Paul, MN) - See all my reviews
This review is from: .NET Framework Security (Paperback)
It's probably not going to make your in-laws love you, but it is the right book for .Net. Like all things digital, .Net programming has already resulted in a number of books, mostly of shoddy quality. This book, however, written by the folks who ought to know (Sebastian Lange and company), is the best place to start, and until they update it, the best place to stay.But it won't make your in-laws love you.
4 of 8 people found the following review helpful:
5.0 out of 5 stars
In depth,
By
Amazon Verified Purchase(What's this?)
This review is from: .NET Framework Security (Paperback)
Excellent and indepth... although it starts out slow.If you really want to know all there is to know about code access security, this is the book for you. This is *not* for beginners. |
|
Most Helpful First | Newest First
|
|
.NET Framework Security by Kevin T. Price (Paperback - April 24, 2002)
Used & New from: $0.01
| ||